Marmot-TS
    Preparing search index...

    Function decryptMediaFileWithKeys

    • Decrypts a fetched encrypted-media-v1 blob, trying each candidate key in order until one authenticates the ciphertext.

      The media file key is derived from the source-epoch media exporter secret (features/encrypted-media.md — Key Derivation), but the source epoch is not carried in the imeta tag. Rather than thread the source epoch through every caller, the receiver supplies one key per still-retained epoch (current epoch first) and relies on the AEAD tag to identify the right one. The ciphertext hash is verified once; only the cheap AEAD open is retried per key.

      Parameters

      • encrypted: Uint8Array

        The encrypted blob downloaded from a blob store

      • fileKeys: Uint8Array<ArrayBufferLike>[]

        Candidate keys from deriveMediaEncryptionKey, one per retained epoch; tried in order. MUST be non-empty.

      • attachment: MediaAttachment

        The parsed attachment from the message's imeta tag

      Returns Uint8Array

      The decrypted file bytes from the first key that authenticates

      If no candidate key authenticates the ciphertext, or a check fails